Fedora Linux Support Community & Resources Center

Go Back   FedoraForum.org > Fedora 17/18 > Security and Privacy
FedoraForum Search

Forgot Password? Join Us!

Security and Privacy Sadly, malware, spyware, hackers and privacy threats abound in today's world. Let's be paranoid and secure our penguins, and slam the doors on privacy exploits.

Reply
 
Thread Tools Search this Thread Display Modes
  #1  
Old 8th February 2005, 11:14 PM
zoodayz Offline
Registered User
 
Join Date: Mar 2004
Location: Nebraska USA
Age: 35
Posts: 45
Mozilla / Firefox Spoofing Security Issue 2005-02-07

Just thought I would pass this info on to otheres that may or may not know about it for Mozilla 1.7.x MozillaFirefox 0.x
Mozilla Firefox 1.x
Have a look at the test!
http://secunia.com/advisories/14163/

Be carefull! ZoodayZ...

Last edited by zoodayz; 8th February 2005 at 11:19 PM.
Reply With Quote
  #2  
Old 9th February 2005, 02:42 AM
greatscot
Guest
 
Posts: n/a
Yes, however, there is a workaround. Type about:config into the browser address bar and hit the enter key.
Look for the following entry: network.enableIDN
Highlight that entry and double-click it to change the boolean value from true to false.
This will disallow a malicious webpage, that attempts to exploit this vulnerability, to load at all.
I have tried it on a test webpage and it stops the exploit from working by not allowing the exploit webpage to load

Last edited by greatscot; 9th February 2005 at 02:49 AM.
Reply With Quote
  #3  
Old 9th February 2005, 03:19 AM
mcg Offline
Registered User
 
Join Date: Nov 2004
Posts: 36
This is a temporary workaround, because if you install a new extension, the network.enableIDN takes its old value, no matter what it writes in the about:config tab. The real solution is to edit the ~/.mozilla/firefox/xxxxxxxx.default/compreg.dat file by hand and change this string:
Code:
@mozilla.org/network/idn-service;1,{62b778a6-bce3-456b-8c31-2865fbb68c91}
to this :
Code:
@mozilla.org/network/idn-service;0,{62b778a6-bce3-456b-8c31-2865fbb68c91}
Reply With Quote
  #4  
Old 9th February 2005, 03:41 AM
greatscot
Guest
 
Posts: n/a
mcg: Thank you for that tip
Reply With Quote
  #5  
Old 9th February 2005, 06:25 AM
Jman Offline
Registered User
 
Join Date: Mar 2004
Location: Minnesota, USA
Age: 27
Posts: 7,909
Subtle! I didn't even notice the strange character in the test, and I usually notice things like that.
Reply With Quote
  #6  
Old 11th February 2005, 01:00 AM
RedFedora's Avatar
RedFedora Offline
Registered User
 
Join Date: May 2004
Posts: 503
Seems the web browser I use (Opera) is also vunerable. Any known work arounds for Opera yet?
__________________
Registered Linux User # 373325
Reply With Quote
  #7  
Old 11th February 2005, 03:08 AM
bob's Avatar
bob Offline
Administrator (yeah, back again)
 
Join Date: Jul 2004
Location: Colton, NY; Junction of Heaven & Earth (also Routes 56 & 68).
Age: 67
Posts: 21,225
According to Digg, the 2/10/05 build of Mozilla and Firefox has corrected the security issue. Available here: http://ftp.mozilla.org/pub/mozilla.o...t-aviary1.0.1/
__________________
Linux & Beer - That TOTALLY Computes!
Registered Linux User #362651


Don't use any of my solutions on working computers or near small children.
Reply With Quote
Reply

Tags
firefox, mozilla, security, spoofing

Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Mozilla Firefox 64-bit trademark issue? IrishBouzouki Using Fedora 3 11th February 2009 11:38 PM
Red Hat Magzine June 2005 Issue #8 tchung News 1 20th June 2005 12:54 AM
Red Hat Magazine, Issue #6, April 2005 tchung News 1 15th April 2005 11:08 AM


Current GMT-time: 06:05 (Saturday, 25-05-2013)

TopSubscribe to XML RSS for all Threads in all ForumsFedoraForumDotOrg Archive
logo

All trademarks, and forum posts in this site are property of their respective owner(s).
FedoraForum.org is privately owned and is not directly sponsored by the Fedora Project or Red Hat, Inc.

Privacy Policy | Term of Use | Posting Guidelines | Archive | Contact Us | Founding Members

Powered by vBulletin® Copyright ©2000 - 2012, vBulletin Solutions, Inc.

FedoraForum is Powered by RedHat